Data packet real-time filtering method and device of vehicle-mounted host firewall
By monitoring the vehicle status in real time and updating the packet filtering rules, the existing vehicle host firewall cannot meet the filtering and detection needs of complex vehicle application scenarios, and improve the safety and reliability of vehicle applications.
Patent Information
- Application Number
- CN202510343467.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-27
AI Technical Summary
The existing vehicle host firewall cannot meet the needs of data packet filtering and detection in a timely manner in complex vehicle application scenarios, resulting in low safety and reliability of vehicle applications.
By receiving the preset rule set sent by the host computer, the vehicle status is monitored in real time, and the corresponding packet filtering rules are determined from the preset rule set based on the current status, and the various protocol layer data of the network traffic data packets are analyzed and filtered. If the vehicle state changes, the filtering rules are updated to adapt to the new state.
It realizes accurate filtering and detection of data packets in complex vehicle application scenarios, and improves the network security and reliability of vehicle applications.
Smart Images

Figure CN120223383A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of in-vehicle host firewall applications, and in particular, to a method and device for real-time filtering of data packets of an in-vehicle host firewall. Background Art
[0002] The in-vehicle host firewall is an important component module of the adaptive platform AUTOSAR AP. The in-vehicle host firewall can detect the incoming and outgoing traffic of the ECU, timely discover threats, block the threat traffic, and improve the network security level of the whole vehicle.
[0003] However, through research by the inventor, it is found that the current firewall design is mainly based on partial network layer detection and filtering of data packets. However, the actual vehicle application scenarios are relatively complex and changeable. Different vehicle application situations require different data packet filtering rules, and the operation is relatively cumbersome; and the current in-vehicle host firewall cannot timely meet the actual application requirements of the vehicle to filter and detect data packets, so the safety and reliability of vehicle applications are not high. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a method and device for real-time filtering of data packets of an in-vehicle host firewall, so as to alleviate the technical problem that the in-vehicle host firewall in the prior art cannot accurately filter data packets to meet the requirements of complex vehicle application scenarios.
[0005] In a first aspect, the present invention provides a method for real-time filtering of data packets of an in-vehicle host firewall, including:
[0006] Receiving a preset rule set sent by a host computer; wherein, the preset rule set is used to represent the filtering rules of data of each protocol layer for network traffic data packets to be transmitted under each vehicle state; the data of each protocol layer includes link layer data, network layer data, transport layer data, and application layer data;
[0007] Real-time monitoring of the vehicle state of the current vehicle, determining a first filtering rule for the current network traffic data packet from the preset rule set based on the first vehicle state of the current vehicle, and parsing and filtering the data of each protocol layer of the current network traffic data packet;
[0008] If the current vehicle switches from the first vehicle state to the second vehicle state, then determine the application layer data filtering rule and / or transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the first filtering rule to generate a second filtering rule, and parse and filter the data of each protocol layer of the current network traffic data packet based on the second filtering rule.
[0009] In an alternative embodiment, the step of determining a first filtering rule for a current network traffic data packet from the preset rule set based on a first vehicle state of the current vehicle, and parsing and filtering data of each protocol layer of the current network traffic data packet includes:
[0010] Search from the preset rule set based on the first vehicle state of the current vehicle, and respectively determine a first filtering rule for first protocol layer data of the current network traffic data packet and a first filtering rule for second protocol layer data; wherein, the first protocol layer data is link layer data, network layer data, and transport layer data; the second protocol layer data is application layer data;
[0011] Based on a hook function in the kernel state of the in-vehicle host and the first filtering rule for the first protocol layer data, intercept the current network traffic data packet, and parse and filter the first protocol layer data in the current network traffic data packet;
[0012] Based on the first filtering rule for the second protocol layer data and a preset parsing function corresponding to the protocol type of the second protocol layer data in the current network traffic data packet, parse and filter the second protocol layer data.
[0013] In an alternative embodiment, the step of parsing and filtering the second protocol layer data based on the first filtering rule for the second protocol layer data and a preset parsing function corresponding to the protocol type of the second protocol layer data in the current network traffic data packet includes:
[0014] Based on the transport layer data and application layer data in the current network traffic data packet, determine the protocol type corresponding to the application layer data in the current network traffic data packet;
[0015] According to the first filtering rule for the application layer data in the current network traffic data packet and the preset parsing function corresponding to the protocol type, parse and filter the application layer data in the current network traffic data packet.
[0016] In an alternative embodiment, the step of determining the protocol type corresponding to the application layer data in the current network traffic data packet based on the transport layer data and application layer data in the current network traffic data packet includes:
[0017] Based on the comparison consistency between the port number of the transport layer data in the current network traffic data packet and a preset port number, determine a first protocol type of the application layer data in the current network traffic data packet; wherein, the first protocol type includes the DOIP protocol type;
[0018] Determine the second protocol type of the application layer data in the current network traffic packet based on the comparison consistency between the target byte content and the preset byte content in the application layer data of the current network traffic packet; wherein, the target byte content includes the data length, protocol version, and protocol interface version; the second protocol type includes the DDS protocol type and the SOME / IP protocol type.
[0019] In an alternative embodiment, if the current vehicle switches from the first vehicle state to the second vehicle state, the step of determining the application layer data filtering rule and / or the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set and updating the first filtering rule to generate the second filtering rule includes:
[0020] If there is a filter for the network traffic packet of the basic function in the first vehicle state or the second vehicle state, obtain the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the transport layer data filtering rule corresponding to the first vehicle state in the first filtering rule;
[0021] If there is a filter for the network traffic packet of the service function in the first vehicle state or the second vehicle state, obtain the application layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the application layer data filtering rule corresponding to the first vehicle state in the first filtering rule;
[0022] Generate a second filtering rule for parsing and filtering the data of each protocol layer of the current network traffic packet based on the updated first filtering rule.
[0023] In an alternative embodiment, the step of real-time monitoring the vehicle state of the current vehicle includes:
[0024] If the current vehicle has multiple vehicle states at the same time, according to the security priority corresponding to each vehicle state, use the vehicle state with the highest security priority as the real-time vehicle state of the current vehicle.
[0025] In an alternative embodiment, the step of receiving the preset rule set sent by the host computer includes:
[0026] Load the configuration file of the preset rule set sent by the host computer, and read the preset rule set into the memory.
[0027] In a second aspect, the present invention provides a real-time packet filtering device for an in-vehicle host firewall, including:
[0028] A receiving module that receives a preset rule set sent by a host computer; wherein the preset rule set is used to represent the filtering rules of data at each protocol layer for network traffic data packets to be transmitted under each vehicle state; the data at each protocol layer includes link layer data, network layer data, transport layer data, and application layer data;
[0029] A first filtering module that monitors the vehicle state of the current vehicle in real time, determines the first filtering rule of the current network traffic data packet from the preset rule set based on the first vehicle state of the current vehicle, and parses and filters the data at each protocol layer of the current network traffic data packet;
[0030] A second filtering module, if the current vehicle switches from the first vehicle state to the second vehicle state, determines the application layer data filtering rule and / or transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, updates the first filtering rule to generate a second filtering rule, and parses and filters the data at each protocol layer of the current network traffic data packet based on the second filtering rule.
[0031] In a third aspect, the present invention provides an electronic device, including a memory and a processor. A computer program that can run on the processor is stored in the memory. When the processor executes the computer program, the steps of the method described in any one of the foregoing embodiments are implemented.
[0032] In a fourth aspect, the present invention provides a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions cause the processor to implement the steps of the method described in any one of the foregoing embodiments.
[0033] A method and device for real-time filtering of data packets of an in-vehicle host firewall provided by an embodiment of the present invention obtain the filtering rules corresponding to each protocol layer in network traffic data packets in each vehicle state from a host computer; monitor the current vehicle state in real time. If the vehicle is in the first vehicle state, determine the filtering rules for each protocol layer from the preset rule set based on the first vehicle state and parse and filter the current network traffic data packet; if the current vehicle changes from the first vehicle state to the second vehicle state, update the original filtering rule based on the application layer and / or transport layer filtering rules corresponding to the second vehicle state obtained from the preset rule set, and then parse and filter the current network traffic data packet, which can more timely and conveniently adapt to complex vehicle application scenarios and ensure the transmission security of network traffic data packets in various vehicle application scenarios.
[0034] Other features and advantages of the present disclosure will be set forth in the following description, or can be learned by inference from the description or be definitely determined without doubt, or can be learned by implementing the above technologies of the present disclosure.
[0035] To make the above objects, features, and advantages of the present disclosure more apparent and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, details are described as follows. Brief Description of the Drawings
[0036] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0037] Figure 1 It is a flowchart of a method for real-time packet filtering of an in-vehicle host firewall provided by an embodiment of the present invention;
[0038] Figure 2 It is a schematic diagram of an application scenario of a method for real-time packet filtering of an in-vehicle host firewall provided by an embodiment of the present invention;
[0039] Figure 3 It is a functional module diagram of a device for real-time packet filtering of an in-vehicle host firewall provided by an embodiment of the present invention;
[0040] Figure 4 It is a schematic diagram of the hardware architecture of an electronic device provided by an embodiment of the present invention. Detailed Embodiments
[0041] To make the objects, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention in conjunction with the drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0042] Through research, the inventor found that in actual projects, to ensure the safe and reliable operation of vehicle applications, it is necessary to timely adjust the network traffic of the input / output ECU module according to the real-time vehicle state.
[0043] Based on this, a method and device for real-time packet filtering of an in-vehicle host firewall provided by an embodiment of the present invention can quickly switch the filtering rules of each protocol layer of the current network traffic packet based on the real-time vehicle state, thereby ensuring the security and reliability of the network traffic data transmitted between ECU modules.
[0044] For the convenience of understanding this embodiment, first, a method for real-time filtering of data packets of an in-vehicle host firewall disclosed in the embodiments of the present invention will be introduced in detail. This method is applied to the in-vehicle host firewall and includes an execution agent of the in-vehicle host firewall (FW) in the user state and an execution engine of the in-vehicle host firewall (FW) in the kernel state.
[0045] Figure 2 It is a schematic diagram of the application scenario of a method for real-time filtering of data packets of an in-vehicle host firewall provided by the embodiments of the present invention.
[0046] Through the linkage of the in-vehicle host firewall with the upper computer and the APP application program in the user state, the dimension of the vehicle state is added to the data filtering rules of each protocol layer of the data packet, realizing that the firewall can accurately detect the network traffic data packet according to the real-time vehicle state, that is, under different vehicle states, the corresponding filtering rules are used to ensure the reliability of data transmission.
[0047] Figure 1 It is a flowchart of a method for real-time filtering of data packets of an in-vehicle host firewall provided by the embodiments of the present invention.
[0048] As Figure 1 shown, the method includes the following steps:
[0049] Step S102, receiving a preset rule set sent by the upper computer.
[0050] Among them, the preset rule set is used to represent the filtering rules of each protocol layer data of the network traffic data packet to be transmitted under the action of each vehicle state; each protocol layer data includes link layer data, network layer data, transport layer data and application layer data.
[0051] Step S104, real-time monitoring the vehicle state of the current vehicle, determining the first filtering rule of the current network traffic data packet from the preset rule set based on the first vehicle state of the current vehicle, and parsing and filtering each protocol layer data of the current network traffic data packet.
[0052] It can be understood that the preset rule set includes the filtering rules of network traffic data packets corresponding to various vehicle states set in advance; each vehicle state includes at least one filtering rule of network traffic data packets; for example, in the case of vehicle state A, while filtering data B, data C also needs to be filtered synchronously.
[0053] Step S106, if the current vehicle switches from the first vehicle state to the second vehicle state, determine the application layer data filtering rule and / or the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, update the first filtering rule to generate the second filtering rule, and parse and filter the data of each protocol layer of the current network traffic packet based on the second filtering rule.
[0054] Here, if the vehicle state changes, the application layer data filtering rule and / or the transport layer data filtering rule corresponding to the current latest vehicle state can replace the application layer data and / or the transport layer data filtering rule corresponding to the original vehicle state, which can quickly implement the parsing and filtering of the current network traffic packet according to the latest vehicle state and improve the data transmission reliability between ECU modules.
[0055] In a preferred embodiment of practical application, for the method and device for real-time packet filtering of an in-vehicle host firewall, obtain the filtering rules corresponding to each protocol layer in the network traffic packet in each vehicle state from the upper computer; monitor the current vehicle state in real time. If the vehicle is in the first vehicle state, parse and filter the current network traffic packet based on the filtering rules of each protocol layer determined from the preset rule set according to the first vehicle state; if the current vehicle changes from the first vehicle state to the second vehicle state, update the original filtering rules based on the application layer and / or transport layer filtering rules corresponding to the second vehicle state obtained from the preset rule set, and then parse and filter the current network traffic packet, which can more timely and conveniently adapt to complex vehicle application scenarios and ensure the transmission security of network traffic packets in various vehicle application scenarios.
[0056] In some embodiments, step S102 can obtain the preset rule set through the following steps, including:
[0057] Step 1.1), load the configuration file of the preset rule set sent by the upper computer and read the preset rule set into the memory.
[0058] Among them, the upper computer will pre-configure a complete rule set, which is configured according to various vehicle states; for example, configure the vehicle stop state (stoping) for the rule set to detect network traffic packets; configure the vehicle low-speed driving state (runninglow, speed less than 30 km / h) for the rule set to detect network traffic packets; configure the vehicle high-speed driving state (runningfast, speed greater than 30 km / h) for the rule set to detect network traffic packets, etc. After the upper computer is configured, generate a configuration file in json format for the preset rule set, send it to the FW execution agent, and store it in the memory.
[0059] In practical applications, step S104 can use the APP application in the user state to monitor the vehicle status of the current vehicle in real time and send it to the FW execution agent. Based on this, subsequent steps can parse and filter network traffic data packets according to the latest vehicle status; for the FW execution agent, it can determine the real-time vehicle status of the current vehicle based on the issued vehicle status, including:
[0060] Step 2.1), if there are multiple vehicle statuses for the current vehicle at the same time, then according to the security priority corresponding to each vehicle status, the vehicle status with the highest security priority is used as the real-time vehicle status of the current vehicle.
[0061] It should be noted that the current vehicle may be in a vehicle stop state and a vehicle charging state at the same time. The priorities are divided according to the safety criticality of the vehicle stop state and the vehicle charging state in practical applications, that is, the safety priority of the vehicle charging state is higher than that of the vehicle stop state; at this time, the vehicle charging state with the highest safety priority is used as the real-time vehicle status of the current vehicle.
[0062] Based on the vehicle status determined in the foregoing embodiment, the steps of finding the corresponding first filtering rule and parsing and filtering the data of each protocol layer of the current network traffic data packet include:
[0063] Step 3.1), search from the preset rule set based on the first vehicle status of the current vehicle, and respectively determine the first filtering rule for the first protocol layer data and the first filtering rule for the second protocol layer data of the current network traffic data packet.
[0064] Among them, the first protocol layer data is link layer data, network layer data, and transport layer data; the second protocol layer data is application layer data.
[0065] When the FW execution agent starts, it loads the configuration file of the preset rule set, reads the configuration file into the memory, and in the memory, in the data structure of map<key,value>, the key is the current vehicle status, and the value is the filtering rule set of the network traffic data packet corresponding to the current vehicle status.
[0066] Step 3.2), based on the hook function in the kernel state of the in-vehicle host and the first filtering rule of the first protocol layer data, intercept the current network traffic data packet, and parse and filter the first protocol layer data in the current network traffic data packet.
[0067] Exemplarily, specifically, the following includes:
[0068] Step 3.21), register the hook function with the network firewall in the kernel state in advance.
[0069] Using the struct nf_hook_ops structure provided by the in-vehicle host firewall netfilter in the kernel mode, a hook function is registered in the structure. The role of the hook function is to divert the data stream in the kernel for subsequent parsing and filtering processing. Specifically, the registration of the hook function can be implemented through the following code:
[0070] nf_blockicmppkt_ops = (struct nf_hook_ops*)kcalloc(1, sizeof(struct nf_hook_ops), GFP_KERNEL);
[0071] nf_blockicmppkt_ops->hook = (nf_hookfn*)validatePacket;
[0072] Among them, the above-registered validatePacket function is a hook function. After such registration, under the action of the hook function, the kernel will intercept and introduce the network traffic data packets.
[0073] Step 3.22), based on the hook function, intercept the network traffic data packets to be transmitted.
[0074] After registering the hook function, the network data packets will be diverted to the hook function for subsequent steps to be executed.
[0075] Step 3.23), according to the filtering rules of the first protocol layer data in the network traffic data packet, respectively parse and filter the data link layer data, network layer data, and transport layer data in the network traffic data packet.
[0076] Specifically, inside the hook function, the struct ethhdr defined in the system is used to parse the data link layer data (the content of the data link layer protocol header) in the network traffic data packet, the struct iphdr is used to parse the network layer data (the content of the network layer protocol header) in the network traffic data packet, and the struct tcphdr and struct udphdr are used to parse the transport layer data (the content of the transport layer protocol header) in the network traffic data packet.
[0077] Step 3.3), based on the first filtering rule of the second protocol layer data and the preset parsing function corresponding to the protocol type of the second protocol layer data in the current network traffic data packet, parse and filter the second protocol layer data.
[0078] Exemplarily, it can be implemented through the following steps:
[0079] Step 3.31), based on the transport layer data and application layer data in the current network traffic packet, determine the protocol type corresponding to the application layer data in the current network traffic packet.
[0080] Exemplarily, it can be achieved through the following steps. Based on the data state of the application layer data when it is not parsed, determine its application layer parsing type, and then select the corresponding parsing function to achieve the subsequent parsing and filtering purpose, specifically including:
[0081] Step 3.311), based on the comparison consistency between the port number of the transport layer data in the network traffic packet to be transmitted and the preset port number, determine the first protocol type of the application layer data in the network traffic packet; wherein, the first protocol type includes the DOIP protocol type.
[0082] For example, pre-set the preset port number 13400 corresponding to the DOIP protocol. Based on the above-mentioned step S104, the port number of the transport layer data can be obtained after parsing the transport layer data; compare this port number with the preset port number; if the two are consistent, the application protocol of the application layer data of the current network quantity packet is the DOIP protocol type. At this time, the application layer data can be diverted to the parsing function corresponding to the DOIP protocol type to achieve parsing, and step 3.312) does not need to be executed anymore; if the two are inconsistent, then execute step 3.312).
[0083] Step 3.312), based on the comparison consistency between the target byte content and the preset byte content of the application layer data in the network traffic packet to be transmitted, determine the second protocol type of the application layer data in the network traffic packet.
[0084] It can be understood that the application layer data in the unparsed state is generally 50 / 100-byte data in binary or hexadecimal, and its target byte content can be initially seen. The target byte content includes the data length, protocol version, and protocol interface version.
[0085] In practical applications, the target byte content corresponding to the application layer data of the second protocol type, that is, the preset byte content, can be pre-set; the second protocol type includes the DDS protocol type and the SOME / IP protocol type. For example, starting from the fourth byte of the application layer data corresponding to the SOME / IP protocol, count four bytes, and the content representing the data length can be taken out. The thirteenth byte is the protocol version of SOME / IP, and the protocol version of SOME / IP is 0x01. The fourteenth byte is the protocol interface version 0x01 of SOME / IP; another example is that the first four bytes of the application layer data corresponding to the DDS protocol are 'R', 'T', 'P','S' respectively, and two bytes are taken starting from the eleventh byte to represent the data length.
[0086] Determine the application layer protocol type corresponding to the current network traffic data packet according to the target byte content of the actual application layer data and the matching situation of the preset byte content.
[0087] In step 3.32), according to the first filtering rule of the application layer data in the current network traffic data packet and the preset parsing function corresponding to the protocol type, parse and filter the application layer data in the current network traffic data packet.
[0088] Based on the application layer protocol type determined in the foregoing embodiments, select the corresponding parsing function to parse the application layer data, and filter the application layer data in the network traffic data packet through the filtering rule of the application layer data. Thus, the in-vehicle host firewall realizes the parsing and filtering of all protocol layer data of the network traffic data packet to be transmitted. For example, the validateDoIPPacket function is the parsing function of DoIP. Inside the validateDoIPPacket function, parse the application layer data of the DoIP application layer protocol and perform threat discovery operations.
[0089] In some embodiments, if the vehicle state changes, the filtering rule can be quickly switched, thereby ensuring the reliability of the data transmitted between ECU modules; exemplarily, step S106 can be implemented through the following steps, including:
[0090] In step 4.1), if there is a filtering of the network traffic data packet for the basic function in the first vehicle state or the second vehicle state, obtain the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the transport layer data filtering rule corresponding to the first vehicle state in the first filtering rule; based on the updated first filtering rule, generate a second filtering rule for parsing and filtering each protocol layer data of the current network traffic data packet.
[0091] It should be noted that if the first vehicle state at the previous moment and the second vehicle state at the current moment belong to the same type, and each vehicle state is to filter the network traffic data packet for realizing the basic function, at this time, it can be known that the definition of the basic function data is preset, that is, the transport layer port number corresponding to each basic function data can be known; that is, in this case, by switching the rule of the transport layer data filtering port number X in the filtering rule corresponding to the first vehicle state to the rule of the transport layer data filtering port number Y in the filtering rule corresponding to the second vehicle state, the update of the second filtering rule can be realized, and there is no need to adjust the filtering rules of the remaining protocol layers. This method realizes the switching of the filtering rule relatively quickly, thereby ensuring the real-time performance of the data packet filtering.
[0092] For example, when the vehicle is in the online upgrade state, in addition to the normal OTA online upgrade, other file transfer ports such as port 21 of FTP and peripheral ports such as port 22 of SSH are not allowed to connect and upload files; that is, the transport layer filtering rule corresponding to the vehicle online upgrade state is to filter the data of port 21 and port 22; if a certain vehicle also has data filtering for basic functions, only the transport layer filtering rule needs to be updated, that is, update the filtering port number to implement the filtering of different basic function data.
[0093] In step 4.2), if there is filtering for the network traffic data packets of the service function in the first vehicle state or the second vehicle state, obtain the application layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the application layer data filtering rule corresponding to the first vehicle state in the first filtering rule; based on the updated first filtering rule, generate a second filtering rule for parsing and filtering the data of each protocol layer of the current network traffic data packet.
[0094] It should be noted that if the first vehicle state at the previous moment and the second vehicle state at the current moment belong to the same type, and each vehicle state filters the network traffic data packets used to implement the service function, at this time, the service IDs of the service functions corresponding to the two vehicle states before and after can be switched and updated at the application layer; that is, in this case, the rule with the application layer data filtering service ID of M in the filtering rule corresponding to the first vehicle state can be switched to the rule with the application layer data filtering service ID of N in the filtering rule corresponding to the second vehicle state to achieve the update of the second filtering rule, without adjusting the filtering rules of the remaining protocol layers. This method can switch the filtering rules more quickly, thereby ensuring the real-time performance of data packet filtering.
[0095] For example, if the first vehicle state is the medium-high speed driving state, then in this state, the door lock unlocking instruction and the door opening instruction need to be intercepted. At this time, the filtering rule is to filter the service IDs in the application layer corresponding to intercepting the door lock unlocking instruction and the door opening instruction respectively; if the second vehicle state is the charging state, then in this state, the vehicle braking instruction and the instruction to supply power to the throttle to make the vehicle drive need to be intercepted. At this time, the filtering rule is to filter the service IDs in the application layer corresponding to intercepting the vehicle braking instruction and the instruction to supply power to the throttle to make the vehicle drive respectively; that is, only updating the service IDs in the application layer from intercepting the door lock unlocking instruction and the door opening instruction to intercepting the vehicle braking instruction and the instruction to supply power to the throttle to make the vehicle drive can achieve the update of the second filtering rule.
[0096] It should be noted that if the first vehicle state at the previous moment and the second vehicle state at the current moment belong to different types, then steps 4.1) and 4.2) in the foregoing embodiments are applied simultaneously. By updating the application layer filtering rule and the transport layer filtering rule, the filtering rule of the network traffic data packet is quickly switched when the vehicle state changes, so as to accurately detect the network traffic data packet.
[0097] As an alternative embodiment, as Figure 2 shown, the vehicle is equipped with an application for real-time recording of the vehicle state. When the vehicle state changes, the APP application sends the current vehicle state information to the FW execution agent. After receiving the vehicle state information, the FW execution agent queries the preset rule set filewallrule of the current vehicle state in the map table, and then sends the rule set to the FW execution engine in the kernel. After receiving the preset rule set filewallrule, the FW execution engine filters and detects the network traffic passing in and out of the current ECU according to the rules for each protocol layer data in the preset rule set. When an illegal data packet is detected, the current data packet is blocked, and an alarm event is sent to the FW execution agent; when the vehicle state changes, for example, from the running state to the stopped state, the APP application sends the current vehicle state information to the FW execution agent again, and then repeats the foregoing steps for determining the data packet filtering rule based on the latest vehicle state.
[0098] The embodiment of the present invention is applied to the host firewall on the ECU, which can replace different rule sets according to the vehicle state, and then perform different detections on network data packets according to the vehicle state, detect different network data packets, making the detection of the firewall more flexible and safer; at the same time, based on the improvement of the firewall rule set, the firewall is layered, and an application process vehicle state notification mechanism is added, making the detection of the host firewall on the ECU more flexible and improving the network security of the ECU at the same time.
[0099] In some embodiments, as Figure 3 shown, the embodiment of the present invention further provides a real-time packet filtering device 200 for a vehicle-mounted host firewall, including:
[0100] A receiving module 201, configured to receive a preset rule set sent by an upper computer; wherein, the preset rule set is used to represent the filtering rules of each protocol layer data of the network traffic data packet to be transmitted under the action of each vehicle state; the each protocol layer data includes link layer data, network layer data, transport layer data and application layer data;
[0101] The first filtering module 202 monitors the vehicle state of the current vehicle in real time, determines the first filtering rule for the current network traffic packet from the preset rule set based on the first vehicle state of the current vehicle, and parses and filters the data of each protocol layer of the current network traffic packet;
[0102] The second filtering module 203, if the current vehicle switches from the first vehicle state to the second vehicle state, determines the application layer data filtering rule and / or the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, updates the first filtering rule to generate a second filtering rule, and parses and filters the data of each protocol layer of the current network traffic packet based on the second filtering rule.
[0103] Further, the first filtering module 202 is further specifically configured to search from the preset rule set based on the first vehicle state of the current vehicle, and respectively determine the first filtering rule for the first protocol layer data of the current network traffic packet and the first filtering rule for the second protocol layer data; wherein, the first protocol layer data is link layer data, network layer data, and transport layer data; the second protocol layer data is application layer data; based on the hook function in the kernel state of the in-vehicle host and the first filtering rule for the first protocol layer data, intercept the current network traffic packet, parse and filter the first protocol layer data in the current network traffic packet; based on the first filtering rule for the second protocol layer data and the preset parsing function corresponding to the protocol type of the second protocol layer data in the current network traffic packet, parse and filter the second protocol layer data.
[0104] Further, the first filtering module 202 is further specifically configured to determine the protocol type corresponding to the application layer data in the current network traffic packet based on the transport layer data and the application layer data in the current network traffic packet; according to the first filtering rule for the application layer data in the current network traffic packet and the preset parsing function corresponding to the protocol type, parse and filter the application layer data in the current network traffic packet.
[0105] Further, the first filtering module 202 is further specifically configured to determine the first protocol type of the application layer data in the current network traffic packet based on the comparison consistency between the port number of the transport layer data in the current network traffic packet and the preset port number; wherein, the first protocol type includes the DOIP protocol type; determine the second protocol type of the application layer data in the current network traffic packet based on the comparison consistency between the target byte content of the application layer data in the current network traffic packet and the preset byte content; wherein, the target byte content includes data length, protocol version, and protocol interface version; the second protocol type includes the DDS protocol type and the SOME / IP protocol type.
[0106] Further, the second filtering module 203 is specifically configured to, if there is filtering of network traffic data packets for basic functions in the first vehicle state or the second vehicle state, obtain the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the transport layer data filtering rule corresponding to the first vehicle state in the first filtering rule; if there is filtering of network traffic data packets for service functions in the first vehicle state or the second vehicle state, obtain the application layer data filtering rule corresponding to the second vehicle state from the preset rule set, and update the application layer data filtering rule corresponding to the first vehicle state in the first filtering rule; based on the updated first filtering rule, generate a second filtering rule for parsing and filtering data of each protocol layer of the current network traffic data packet.
[0107] Further, the first filtering module 202 is specifically configured to, if there are multiple vehicle states of the current vehicle at the same moment, use the vehicle state with the highest security priority as the real-time vehicle state of the current vehicle according to the security priority corresponding to each vehicle state.
[0108] Further, the receiving module 201 is specifically configured to load the configuration file of the preset rule set sent by the host computer and read the preset rule set into the memory.
[0109] Figure 4 This is a schematic diagram of the hardware architecture of the electronic device 300 provided in the embodiment of the present invention. Refer to Figure 4 As shown, the electronic device 300 includes: a machine-readable storage medium 301 and a processor 302, and may further include a non-volatile storage medium 303, a communication interface 304, and a bus 305; wherein, the machine-readable storage medium 301, the processor 302, the non-volatile storage medium 303, and the communication interface 304 complete communication with each other through the bus 305. The processor 302 can execute the machine-executable instructions of the real-time filtering of data packets of the in-vehicle host firewall by reading and executing the machine-readable storage medium 301, and can execute the method for real-time filtering of data packets of the in-vehicle host firewall described in the above embodiments.
[0110] The machine-readable storage medium mentioned in this article can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof.
[0111] The non-volatile medium can be a non-volatile memory, a flash memory, a storage drive (such as a hard disk drive), any type of storage disk (such as an optical disc, a DVD, etc.), or a similar non-volatile storage medium, or a combination thereof.
[0112] It can be understood that the specific operation methods of the functional modules in this embodiment can refer to the detailed descriptions of the corresponding steps in the above method embodiments, and will not be repeated here.
[0113] The computer-readable storage medium provided by the embodiment of the present invention stores a computer program, and when the computer program code is executed, it can implement the data packet real-time filtering method of the in-vehicle host firewall described in any of the above embodiments. For the specific implementation, refer to the method embodiments and will not be elaborated here.
[0114] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.
[0115] In addition, in the description of the embodiments of the present invention, unless otherwise clearly defined and limited, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0116] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0117] Finally, it should be noted that the above-described embodiments are only specific embodiments of the present invention, used to illustrate the technical solutions of the present invention, rather than limiting it. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions described in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the protection scope of the present invention.
Claims
1. A method for real-time filtering of data packets of a vehicle-mounted host firewall, characterized in that: include: Receive a preset rule set sent by a host computer; wherein the preset rule set is used to characterize filtering rules of each protocol layer data under each vehicle state for the network traffic data packet to be transmitted; the each protocol layer data includes link layer data, network layer data, transport layer data and application layer data; Monitor the vehicle state of the current vehicle in real time, determine a first filtering rule for the current network traffic data packet from the preset rule set based on the first vehicle state of the current vehicle, and parse and filter data of each protocol layer of the current network traffic data packet; If the current vehicle switches from the first vehicle state to the second vehicle state, the application layer data filtering rules and / or transport layer data filtering rules corresponding to the second vehicle state are determined from the preset rule set, and the first filtering rules are updated to generate second filtering rules, and the various protocol layer data of the current network traffic data packet are parsed and filtered based on the second filtering rules.
2. The method according to claim 1, characterized in that The step of determining a first filtering rule for a current network traffic data packet from the preset rule set based on the first vehicle state of the current vehicle, and parsing and filtering each protocol layer data of the current network traffic data packet comprises: Based on the first vehicle state of the current vehicle, searching from the preset rule set, respectively determining the first filtering rule for the first protocol layer data and the first filtering rule for the second protocol layer data of the current network traffic data packet; wherein the first protocol layer data is link layer data, network layer data and transport layer data; and the second protocol layer data is application layer data; Based on the hook function in the kernel state of the vehicle-mounted host and the first filtering rule of the first protocol layer data, intercept the current network traffic data packet, and parse and filter the first protocol layer data in the current network traffic data packet; The second protocol layer data is parsed and filtered based on the first filtering rule of the second protocol layer data and a preset parsing function corresponding to the protocol type of the second protocol layer data in the current network traffic data packet.
3. The method according to claim 2, characterized in that The step of parsing and filtering the second protocol layer data based on the first filtering rule of the second protocol layer data and the preset parsing function corresponding to the protocol type of the second protocol layer data in the current network traffic data packet includes: Determine, based on the transport layer data and the application layer data in the current network traffic data packet, a protocol type corresponding to the application layer data in the current network traffic data packet; According to the first filtering rule of the application layer data in the current network traffic data packet and the preset parsing function corresponding to the protocol type, the application layer data in the current network traffic data packet is parsed and filtered.
4. The method according to claim 3, characterized in that The step of determining the protocol type corresponding to the application layer data in the current network traffic data packet based on the transport layer data and the application layer data in the current network traffic data packet comprises: Determine the first protocol type of the application layer data in the current network traffic data packet based on the comparison consistency between the port number of the transport layer data in the current network traffic data packet and the preset port number; wherein the first protocol type includes the DOIP protocol type; Based on the comparison consistency between the target byte content and the preset byte content of the application layer data in the current network traffic data packet, the second protocol type of the application layer data in the current network traffic data packet is determined; wherein the target byte content includes data length, protocol version and protocol interface version; the second protocol type includes DDS protocol type and SOME / IP protocol type.
5. The method according to claim 1, characterized in that If the current vehicle switches from the first vehicle state to the second vehicle state, the step of determining the application layer data filtering rule and / or the transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, and updating the first filtering rule to generate the second filtering rule includes: If there is filtering of network traffic data packets for basic functions in the first vehicle state or the second vehicle state, obtaining a transport layer data filtering rule corresponding to the second vehicle state from the preset rule set, and updating the transport layer data filtering rule corresponding to the first vehicle state in the first filtering rule; If there is filtering of network traffic data packets for business functions in the first vehicle state or the second vehicle state, obtaining an application layer data filtering rule corresponding to the second vehicle state from the preset rule set, and updating the application layer data filtering rule corresponding to the first vehicle state in the first filtering rule; Based on the updated first filtering rule, a second filtering rule is generated for parsing and filtering the data of each protocol layer of the current network traffic data packet.
6. The method according to claim 1, characterized in that The steps of real-time monitoring of the vehicle status of the current vehicle include: If the current vehicle has multiple vehicle states at the same time, then according to the safety priority corresponding to each vehicle state, the vehicle state with the highest safety priority is used as the real-time vehicle state of the current vehicle.
7. The method according to claim 1, characterized in that The step of receiving the preset rule set sent by the host computer includes: The configuration file of the preset rule set sent by the host computer is loaded, and the preset rule set is read into the memory.
8. A real-time data packet filtering device for a vehicle-mounted host firewall, characterized in that: include: A receiving module receives a preset rule set sent by a host computer; wherein the preset rule set is used to characterize filtering rules of each protocol layer data under each vehicle state for a network traffic data packet to be transmitted; the each protocol layer data includes link layer data, network layer data, transport layer data and application layer data; A first filtering module monitors the vehicle state of the current vehicle in real time, determines a first filtering rule of the current network traffic data packet from the preset rule set based on the first vehicle state of the current vehicle, and parses and filters data of each protocol layer of the current network traffic data packet; The second filtering module, if the current vehicle switches from the first vehicle state to the second vehicle state, determines the application layer data filtering rules and / or transport layer data filtering rules corresponding to the second vehicle state from the preset rule set, updates the first filtering rules to generate second filtering rules, and parses and filters the various protocol layer data of the current network traffic data packet based on the second filtering rules.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to implement the steps of the method described in any one of claims 1 to 7.
Citation Information
Cited By
Data packet filtering method and device, storage medium and electronic equipment
CN121367918A